First published: Wed Feb 15 2017(Updated: )
The ff_put_pixels8_xy2_mmx function in rnd_template.c in Libav 11.7 allows remote attackers to cause a denial of service (invalid memory access and crash) via a crafted mp3 file. NOTE: this issue was originally reported as involving a NULL pointer dereference.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libavutil | =11.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7477 has a severity level that allows remote attackers to cause a denial of service.
Fixing CVE-2016-7477 involves upgrading Libav to the latest version beyond 11.7.
The denial of service in CVE-2016-7477 is caused by an invalid memory access triggered by a crafted MP3 file.
Yes, CVE-2016-7477 specifically affects Libav version 11.7.
Yes, CVE-2016-7477 can be exploited remotely by sending a specially crafted MP3 file.